Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an Azure Key Vault named kv-contoso that holds an RSA key named AppKey. The key already has an expiry date set to one year after creation. Security policy states that a new version of the key must be generated automatically 30 days before the current version expires, without requiring additional scripts or external services. Which configuration should you apply to meet this requirement?
Assign an Azure Policy that audits keys older than 30 days without rotation.
Update the rotation policy of AppKey to include a lifetime action of rotate that runs 30 days before the key's expiry.
Enable soft-delete and purge protection on kv-contoso.
Create an Azure Automation runbook that calls az keyvault key rotate on a 30-day schedule.
Key Vault performs automatic key rotation only when the key has an explicit rotation policy that contains a lifetime action of rotate. By updating the rotation policy for AppKey so that it triggers a rotate action 30 days before the key's expiry, Key Vault will automatically create a new key version on schedule. Enabling soft-delete or purge protection improves recoverability but does not rotate keys. An Azure Automation runbook could rotate the key, but it introduces an external dependency rather than using the built-in Key Vault capability. An Azure Policy assignment can audit key age but cannot itself create new key versions.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Key Vault rotation policy?
Open an interactive chat with Bash
What is the benefit of using automatic key rotation in Azure Key Vault?
Open an interactive chat with Bash
What is the difference between soft-delete and automatic key rotation?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .